CVE-2021-24568
The AddToAny Share Buttons plugin versions prior to 1.7.46 contain a Cross-Site Scripting vulnerability in its Sharing Header setting. The plugin fails to properly sanitize this setting before displaying it on the frontend, enabling administrators and other high-privilege users to inject malicious scripts even in environments where the unfiltered_html capability has been restricted. This flaw allows authenticated attackers with sufficient permissions to execute arbitrary JavaScript in the context of the website.
Based on public CVE data (MITRE/NVD).